LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the in-app messaging system (both subject and message bodies).
| Software | From | Fixed in |
|---|---|---|
| logicaldoc / logicaldoc | 8.8.2 | 8.8.2.x |
| logicaldoc / logicaldoc | 8.7.3 | 8.7.3.x |